Integer Underflow in JusticeRage Manalyze PE Parser Component
CVE-2026-94090

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 September 2026

What is CVE-2026-94090?

A security flaw has been identified in the JusticeRage Manalyze software version 1.0.0, specifically within the PE Parser component. The vulnerability arises from the function PE::_parse_debug in the file manape/pe.cpp, where manipulation of the argument misc.Length can lead to an integer underflow condition. This can potentially allow an attacker to exploit the flaw remotely, raising significant security concerns. Users are advised to apply the provided patch to mitigate this issue effectively.

Affected Version(s)

Manalyze 1.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

akbarov (VulDB User)
.